Bugwatch: Managing network security risk
Grok Headline matches for Bugwatch: Managing network security risk
Managing network security risk
Managing network security risk
09/17/2004 08:08 PMPersonal Computer World Sep 18 2004 0:42AM GMT
Network Security - Managing risk and
opportunity
Network Security - Managing risk and
opportunity
09/07/2004 08:11 PMComputer Weekly Sep 8 2004 0:34AM GMT
Bugwatch: Managing your users
Bugwatch: Managing your users
04/22/2004 01:35 PMManaging the Network Security Challange
Managing the Network Security Challange
01/06/2004 09:18 AMiPods a network security risk
iPods a network security risk
07/07/2004 12:44 PM“Companies should consider banning portable storage devices such
as Apple’s iPod from corporate networks, as they can be used to
introduce malware or steal corporate data, according to an
analyst.”Well of course they can, as can any other portable
device including company-issued laptops! Anyone remember the CompUSA
incident a couple of years back?
IP phones can create network security
risk
IP phones can create network security
risk
06/20/2004 06:58 AMNetwork security at risk from user
negligence
Network security at risk from user
negligence
07/22/2004 08:18 AMAnalyst: iPods a network security risk
Analyst: iPods a network security risk
07/06/2004 03:12 PMGartner is urging companies to consider banning MP3 players and other
gadgets that could be used to carry malware or steal data.
Network security at risk from user
negligence, report says
Network security at risk from user
negligence, report says
07/21/2004 02:50 PMTacoma Civic Network Decides Hotspots a
Security Risk
Tacoma Civic Network Decides Hotspots a
Security Risk
01/04/2004 02:23 PMTacoma, Washington, has a tremendously ahead-of-its-time fiber optic
link run as a utility by the city, but a hotspot experiment has ended
due to concerns over security: The network tested out a hotspot at one
location, but decided that for security reasons--and also, but less
importantly, lack of projectable revenue--that they'd pull the plug.
As 802.1X and VPNs rise in availability and importance, it may be that
security decisions can be wiped away. If you had a preponderance of
Windows XP and Mac OS X 10.3 users, who have built-in VPN clients for
both IPsec and PPTP as well as secured 802.1X/EAP, then perhaps you
could build a business on the notion that you were offering
100-percent locally encrypted connections. I've wondered why hotspots
don't partner with a VPN ASP and simply provide a free account to
monthly users or a $1 add-on to pay-as-you-go users to give them
permanent (monthly) or disposable (pay-as-you-go) VPN accounts?
(Boingo is the only service to offer VPN as just a part of their
client.)...
Managing Increased Risk
Managing Increased Risk
05/21/2004 06:59 PMTechnology For Finance May 21 2004 10:22PM GMT
Systematically Managing Your Risk
Systematically Managing Your Risk
12/11/2003 04:47 PMmarcus evans Dec 11 2003 2:58PM ET
Managing 802.11b Risk for Enterprises
Managing 802.11b Risk for Enterprises
05/23/2004 09:00 PMEnterprises are reacting sensibly to the issue of low-speed (20 Mbps
or slower) Wi-Fi interference techniques documented by Australian
researchers: It's not so much a flaw as a part of the spec that allows
a certain kind of attack to disable an access point; there are many
others of varying degree of severity, too, including just bringing an
unpleasant 2.4 GHz cordless phone into an office and leaving it turned
on without a connection to a cordless base station. The reaction cited
in this Computerworld article is sensible: managers are examining
their risk and noting that with many access points, an attacker would
have to attack numerous locations at once to have an effect, and would
then be vulnerable to physical detection. All 802.11a and any 802.11g
networks running at faster encodings (using OFDM) can't be attacked in
this fashion, either....
Managing IT risk at Delta Air Lines
Managing IT risk at Delta Air Lines
03/08/2004 11:18 PMIT leaders at Delta Technology Inc., the IT subsidiary of Delta Air
Lines, use an analysis tool based on a curve to measure IT risks and
investments.
Mutual support is key to managing risk
Mutual support is key to managing risk
04/15/2004 09:00 AMPersonal Computer World Apr 15 2004 1:03PM GMT
It Wasn't a Tornado or an Earthquake; it
was an Email. Managing the growing risk
of critical data loss
It Wasn't a Tornado or an Earthquake; it
was an Email. Managing the growing risk
of critical data loss
06/24/2004 07:31 PMBusiness Knowledge Source Jun 24 2004 11:04PM GMT
A RECIPE FOR
MANAGING RISK
A RECIPE FOR
MANAGING RISK
06/06/2004 12:46 PM
Last
week I met with Graham Westwood, CEO of ProCarta Inc. While many
others
are giving up on the promise of 'explicit', 'codified', knowledge to
solve important business problems, ProCarta has found a compelling
niche for the rigorous codification of explicit knowledge: Areas of high risk.
Graham uses the analogy of a 'recipe' to resurrect the reputation of
'best practices'. Rather than a rigid, invariable series of steps that
must be followed precisely to the letter, the procedures, suggestions,
caveats and best practices incorporated into the ProCarta applications
provide a flexible recipe for effectively and efficiently navigating
areas of high business risk. Even a master chef will follow a recipe
the first time he or she tries something new. The flexible nature of
the software allows the ideas, suggestions, newly-discovered best
practices and warnings to be written, wiki-style, into the recipe,
providing additional guidance for other users.
The company's approach to IT is also quite radical: Rather than
sending
IT consultants out to integrate its risk management solutions into the
company's existing IT infrastructure, ProCarta develops its
applications outside the IT infrastructure, as simple, portable,
stand-alone solutions. The business processes involved in addressing
the high-risk problem is analyzed by the user into Processes,
Activities, and Tasks, with each Task assigned to a specific
identified
Role. The regulatory requirements, best practices, and expert guidance
and caveats are then keyed in to each Task. And then with the push of
a
button, the easy-to-use, non-technical ProCarta software produces a
set
of web pages with the corporation's look-and-feel. The resultant
website takes users through each step in the risky process, isolates
the Tasks in each Role, and even turns out job descriptions.
One area where ProCarta's solution has received considerable traction
has been Sarbanes-Oxley Act compliance. 'SOX" compliance procedures
were developed to prevent a recurrence of the Enron/Arthur Andersen
disaster. They address the corporate security environment, division of
responsibilities, new oversight and review responsibilities, and the
auditor attestation process.
To those who shrug off the value of prescribed procedures and best
practices as an unwelcome imposition on the freedom and personal
judgement of professional managers, Graham points out that, where at
one time 'corporate cowboys' were highly respected as individualists,
in high-risk areas they can get the entire business into serious
trouble, leading to jail time or bankruptcy.
As Drucker has often pointed out, in today's business world we are all
subject matter experts, and almost everyone's job is unique. We are
always to some extent the best at what we, uniquely, do. And for that
reason best practices that attempt to capture what someone else does well, have not proven
terribly fertile ground for knowledge transfer. "That might be a best
practice for his
job, but that's not what I do -- my job is different". But in some
high-risk areas, everyone doing something different is not a recipe
for
flexibility and entrepreneurship, but a recipe for disaster.
|
Managing the security of data flow
Managing the security of data flow
06/14/2004 10:02 AMManaging Security for Mobile Users (Part
One)
Managing Security for Mobile Users (Part
One)
04/26/2004 08:22 PMManaging security in a compliance-crazy
world
Managing security in a compliance-crazy
world
03/22/2005 04:22 PMA Pre-emptive Strike: Managing Internet
Security
A Pre-emptive Strike: Managing Internet
Security
07/19/2004 08:00 PMTechnology For Finance Jul 20 2004 0:35AM GMT
Experts: Wireless Network Risk Overhyped
Experts: Wireless Network Risk Overhyped
11/11/2003 01:13 AMIn reality, computer security experts say that the security risks of
wireless networks are no greater than those of regular networks --
provided that the wireless networks are properly configured, their
users are authenticated and the data they carry is encrypted. By Elise
Ackerman (San Jose Mercury News via MyAppleMenu)
Network Protocols Handbook For Cisco
CCNA, CCIE, CCNP, and MCSE, Network+ and
Security+
Network Protocols Handbook For Cisco
CCNA, CCIE, CCNP, and MCSE, Network+ and
Security+
02/01/2005 10:07 PMThe newly released "Network Protocols Handbook" by Javvin is now
distributed by Ingram Books. This book is an excellent reference for
Internet programmers, network pros and for people who are taking
networking technology courses or trying to pass networking related
certifications such as Cisco certification CCNA, CCIE, CCNP, Microsoft
Certification MCSE, CompTIA certification Network+ and Security+.
[PRWEB Jan 26, 2005]
ADV: Free White Paper from Nokia -
Managing Security on Mobile Phones
ADV: Free White Paper from Nokia -
Managing Security on Mobile Phones
06/05/2005 10:58 PMThis white paper describes the challenges of provisioning and managing
security in mobile phone environments and explains how a well-designed
deployment system can alleviate these challenges. This white paper
highlights new technology that Nokia is developing to address the
challenges of transparently managing security like IPSec VPN on mobile
phones.
Protecting Road Warriors: Managing
Security for Mobile Users (Part One)
Protecting Road Warriors: Managing
Security for Mobile Users (Part One)
04/29/2004 10:41 AMProtecting Road Warriors: Managing
Security for Mobile Users (Part Two)
Protecting Road Warriors: Managing
Security for Mobile Users (Part Two)
05/25/2004 07:26 PMNow Everyone Is A Security Risk
Now Everyone Is A Security Risk
07/17/2004 02:54 AMThere is definitely a culture of paranoia and secrecy growing up --
much of it fertilised by attention-seeking analysts. By David Neal, IT
Week (via MyAppleMenu)
Bugwatch: A patch in time
Bugwatch: A patch in time
02/10/2004 02:50 AMBugwatch: Tackling the enemy within
Bugwatch: Tackling the enemy within
03/30/2005 11:39 AMvnunet.com Mar 30 2005 3:27PM GMT
Bugwatch: Lessons from Sasser
Bugwatch: Lessons from Sasser
05/26/2004 07:34 AMPersonal Computer World May 26 2004 11:44AM GMT
Vernier Networks Locks Down Security at
the Network Edge with New EdgeWall
Security Appliance
Vernier Networks Locks Down Security at
the Network Edge with New EdgeWall
Security Appliance
02/01/2005 09:10 PMClientless Network Access Management solution stops internal threats
at the network edge - not the defenseless desktop [PRWEB Feb 1, 2005]
Network Security White Papers Written by
Security Professionals, not Vendors
Network Security White Papers Written by
Security Professionals, not Vendors
03/22/2005 04:55 PMIts getting hard not to notice the number of large websites
advertising white papers. The catch is, most only contain a listing of
vendor sponsored marketing brochures. This isn't very helpful if
you're looking for detailed information about a technology. [PRWEB Mar
21, 2005]
iPod Corporate security risk oh really
iPod Corporate security risk oh really
07/06/2004 05:20 AMLets be honest the people who run your IT department probably have
had iPod's, USB Sticks for a long time. Now the big suprise I bet they
have had them plugged into the corporate network sharing music and
files for the past couple of years with their fellow IT coworkers. So
I am sure they realized long ago that it would be easy for someone to
upload something nasty from home onto the network via one of these
devices. I also bet those IT departments have put in place policies
for such devices.
If your company hasn't then you need to fire you lead IT manager.
One thing the majority of IT professionals don't need, is some analyst
figuring this out about 5 years to late. [ZDNet]
p>
Laziness puts Wi-Fi security at risk
Laziness puts Wi-Fi security at risk
07/22/2004 08:19 PMThe Security Risk of Keyboard Clicks
The Security Risk of Keyboard Clicks
05/13/2004 08:12 AMUK military: iPod is security risk
UK military: iPod is security risk
07/13/2004 07:19 PMiPods are the latest security risk
iPods are the latest security risk
07/07/2004 09:17 AMThumbs down from Gartner
IPods pose security risk for enterprises
IPods pose security risk for enterprises
07/07/2004 07:59 AMComputer Weekly Jul 7 2004 12:29PM GMT
Aus Govt: Proprietary software not a
security risk
Aus Govt: Proprietary software not a
security risk
05/05/2004 09:54 AMGrok Description matches for Bugwatch: Managing network security risk
GrokA matches for Bugwatch: Managing network security risk
Bugwatch: Managing network security risk